Skip to content
supplychainattack.orgSupply chain attack incident catalog
activecritical

Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope

The Shai-Hulud worm has hijacked intercom-client@7.0.4 (361,510 weekly downloads) via a compromised GitHub Actions OIDC publishing pipeline, 29 hours after compromising mbt@1.2.48 and @cap-js/sqlite@2.2.2. The worm is actively propagating through CI/CD infrastructure stolen from earlier victims, targeting multi-cloud credentials (AWS, GCP, Azure).

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Extremely broad. intercom-client@7.0.4 has 361,510 weekly downloads. The package is an official Node.js SDK used across numerous organizations, making this one of the highest-impact npm compromises. CI/CD credentials stolen from prior victims are enabling continued propagation.
Ecosystems
Attack vectors
Threat actor
Affected entities
  • intercom-client · 7.0.4
  • mbt · 1.2.48Compromised prior; CI/CD stolen from this victim
  • @cap-js/sqlite · 2.2.2Compromised prior; CI/CD stolen from this victim

The Shai-Hulud worm campaign has escalated significantly with the compromise of intercom-client@7.0.4, the official Node.js SDK for Intercom's customer messaging platform. This represents the third major npm package hijacked in rapid succession, occurring merely 29 hours after the initial compromises of mbt@1.2.48 and @cap-js/sqlite@2.2.2.

The malicious version was published on May 4, 2026 at 14:41 UTC through a hijacked GitHub Actions OIDC publishing pipeline. This technical detail confirms that the attackers have gained access to CI/CD infrastructure credentials stolen from the victims of the prior two package compromises, enabling automated propagation of the worm across multiple targets.

intercom-client@7.0.4 poses an exceptionally severe risk due to its massive adoption: 361,510 weekly downloads, exceeding the combined download volume of the two previously compromised packages. The worm's expanded scope now includes extraction of cloud credentials across AWS, GCP, and Azure environments, broadening the potential impact from individual organizations to enterprise-scale multi-cloud infrastructure compromise.

This active, ongoing campaign demonstrates sophisticated lateral movement and credential harvesting capabilities, with attackers leveraging stolen CI/CD automation to efficiently compromise high-impact targets in the npm ecosystem.

Indicators of compromise

Packages
  • intercom-client@7.0.4
  • mbt@1.2.48
  • @cap-js/sqlite@2.2.2

Remediation

  • Immediately revoke intercom-client@7.0.4; upgrade to the latest patched version once available from official Intercom maintainers
  • Audit and revoke any npm publish tokens, GitHub Actions secrets, and OIDC credentials that may have been exposed through mbt@1.2.48 or @cap-js/sqlite@2.2.2 compromises
  • Review CI/CD logs for unauthorized package publications or credential exfiltration across all npm packages your organization publishes
  • Rotate all cloud credentials (AWS IAM keys, GCP service accounts, Azure service principals) that may have been present in CI/CD environments or application runtime
  • Monitor for unexpected outbound connections or credential exfiltration attempts from applications using intercom-client@7.0.4
  • Implement stricter OIDC token policies in GitHub Actions, limiting token permissions and implementing audience restrictions
  • Conduct incident response on any systems running intercom-client@7.0.4, treating as potential compromise with multi-cloud credential exposure

Sources

  1. Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope · StepSecurity

Cite this entry

"Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 4, 2026; last updated June 7, 2026. https://supplychainattack.org/incident/shai-hulud-worm-pivots-to-multi-cloud-intercom-client-7-0-4-hijacked-361-000-wee-5p9im6

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/gi-assets-basic (npm)

    A threat actor compromised the npm account 'atool' and published 631 malicious versions across 314 npm packages, including @antv/gi-assets-basic, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g6-extension-3d (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/g6-extension-3d, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in gantt-for-react (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including gantt-for-react, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/gi-sdk-app (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-sdk-app. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit